From nobody Tue Sep 29 02:00:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 326184137BC; Thu, 13 Aug 2026 15:11:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633919; cv=none; b=WZ3Iu6xcNqAIW7L02tOiibXxhGINqQlAhfBknA9SWFadmNyxTqOSZct0ZiwLL3Y5IQwhOt2uZx9JMrPv1FU+xYQXROWjTLi5nxqYqUyk1rvYkxvN4KXGMeYxXck/B/ls1n9tyWKole2l/twXm7RwMQTmuM9+wbRiiVr7sb2IX2U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633919; c=relaxed/simple; bh=aRh6EkoeaT9q41QRhwaIiNb5jAqSXh/lG1c2HMltMOM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=nUIyST7TqyK6uzo3qSa0zD536meCopzk9ke6qypWj0qkrCaDoR3Dfn4I0/AStpz8595pYreUAx6C5GgQhSm5e7yKNy+I3aHgMd0H2Yw7g8CsWHex1Gcp5qfMe/17HR6rnpHffyI65VPwya4bnK3H9a8C7aQNN3wlUz9+vzP6w/A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=PQ+ulL9Y; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="PQ+ulL9Y" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B7CD11F000E9; Thu, 13 Aug 2026 15:11:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786633917; bh=35exvK7MUvcpiE6snTYa6TbYnvczpFFN0RGnE5C80i0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PQ+ulL9YvttMwZTZACQOIagvjbww2MfXexClTCQ+bDup1Zyc+hErztOZL90e/ssYa jtUfdlWwc4N9AIMSmaMCyxKUjb2rKni+MM1fCG900q54QJyc8YGKNQjUhYUWVQ1rKY 9o7WcTjv9m9Sr+Xqd/GY4HPyMKX785qmgBC67xvk/rI1LD4hhMlX4yMc8VSuZlllSO sIYQRiWvXiBMnFu2LVMpltglcocGTaMeF0CFYU+mibaVAWbtiNXnjS8QDRi+ICvFUC OpC82LgEDFh5HFDePfXgPQm76G0rEcev7HcNkebjAGZn/sep2+h0T+BXE3QkttniNx XYOKGRdUpjotg== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot Subject: [PATCH 1/5] perf dso: Guard against errno==0 when dso__get_filename() returns NULL Date: Thu, 13 Aug 2026 12:11:42 -0300 Message-ID: <20260813151148.23169-2-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260813151148.23169-1-acme@kernel.org> References: <20260813151148.23169-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo __open_dso() computes fd =3D -errno when dso__get_filename() returns NULL. Some failure paths in dso__get_filename() (e.g. binary type mismatch) return NULL without making a syscall, leaving errno at 0 from a prior successful call. fd =3D -0 =3D 0, which is stdin =E2=80=94 subsequent code= treats it as a valid file descriptor. Fall back to ENOENT when errno is 0, ensuring fd is always negative on failure. The forced ENOENT stays in errno for the callers that check it after a negative fd. It must not misdirect the try_to_open_dso() fallback loop, though: dso__get_filename()'s chroot fallback used to accept a stale ENOENT even when stat() succeeded on a non-regular file (e.g. a directory). Re-stat() there and only take the chroot path when stat() actually failed with ENOENT [sashiko-bot review of PATCH 1/5]. Fixes: eba5102d2f0b ("perf tools: Add global list of opened dso objects") Reported-by: sashiko-bot Cc: Jiri Olsa Reviewed-by: Ian Rogers Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/dso.c | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c index 2309196d8df3111c..b86969dc6e81e96e 100644 --- a/tools/perf/util/dso.c +++ b/tools/perf/util/dso.c @@ -582,9 +582,18 @@ static char *dso__get_filename(struct dso *dso, const = char *root_dir, goto out; =20 if (!is_regular_file(name)) { + struct stat st; char *new_name; =20 - if (errno !=3D ENOENT || dso__nsinfo(dso) =3D=3D NULL) + /* + * errno only reflects the failure reason when stat() itself + * failed: a successful stat() on a non-regular file (e.g. a + * directory) leaves a stale errno, which a previous failed + * iteration of the try_to_open_dso() fallback loop may have + * set to ENOENT. + */ + if (stat(name, &st) =3D=3D 0 || errno !=3D ENOENT || + dso__nsinfo(dso) =3D=3D NULL) goto out; =20 new_name =3D dso__filename_with_chroot(dso, name); @@ -640,10 +649,13 @@ static int __open_dso(struct dso *dso, struct machine= *machine) mutex_lock(dso__lock(dso)); =20 name =3D dso__get_filename(dso, machine ? machine->root_dir : "", &decomp= ); - if (name) + if (name) { fd =3D do_open(name); - else + } else { + if (errno =3D=3D 0) + errno =3D ENOENT; fd =3D -errno; + } =20 if (decomp) unlink(name); --=20 2.55.0 From nobody Tue Sep 29 02:00:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 59A183B6BE5; Thu, 13 Aug 2026 15:12:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633922; cv=none; b=BZPPv/KO7SZbUoJHCeNfbVv63IEoBaf6WSzz7n2XQ9EwjKn/GLwLY/uVHErcMepYMZQEQOMcuxEyX2eYY7aE01LmCpk+7H+PYdrrPgYB8jGy85IanJe99sx8E7nbMUxig5rY6JYqWqsSmwgkoB1bB/s0HLdFd8PDsjPu46UjYdk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633922; c=relaxed/simple; bh=nrJuzIScqO4BLESZmtMB5DweqQmx1akHlCW8z/DKZ6k=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=kKTCwIxmlIgexZUeLbMTQVBGcCQS0yzvfSWG6geWqE+m3atwpJufc7cIUwGNDQYbL8zJUwMcIkVAIceZU4zh4nzNGqBOxfjm/QhrYZ2t6gSc6PRkxxXq0hnZumKig6CkDcAWPMI7vYDjN7wOTb3HVK4rUBtQJKsZXKN0ncwiqJo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=GCZgJ184; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="GCZgJ184" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 393A81F00A3A; Thu, 13 Aug 2026 15:11:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786633921; bh=9xTgEY+RhaI+JvCVLK3SoMsdrx5fyfqj91XI7HnDn9k=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GCZgJ184NzECzlipJ8Q54mBAz0cgfCW4HMrRjuUN8y6cEmCh7+0+C4zujcbrphO3A zcMttt+6wQBaqVnk34u1TQwPh9t8eamAqFv4SXG+vmY8LrN3a+lqm1YfI/rngSxYhm OUucaL1LmIrJ5jjQvZA8x9eCWAreTBvLvbGthLdeLj7i+syI4mGK/5iMEaZ6WA/O+b JYOs7P+P1a3akI8+0j335Ivv1fbP289PEPY/9b9w6tqoI1Hyo1YFULYOeXNLAa9fz5 Yw04ip/MxmrGZ4PhhRWrmibqbEBHNjanDm5qje0c1MelA5GKIQ7Ri7k1EWgVnjAJ2D XLzWzXtkaXhQA== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot Subject: [PATCH 2/5] perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() Date: Thu, 13 Aug 2026 12:11:43 -0300 Message-ID: <20260813151148.23169-3-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260813151148.23169-1-acme@kernel.org> References: <20260813151148.23169-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo dso__decompress_kmodule_path() unconditionally calls close(fd) on the return value of decompress_kmodule(). When decompression fails or the DSO is not compressed, decompress_kmodule() returns -1. close(-1) fails with EBADF and clobbers errno, which callers up the chain (dso__get_filename =E2=86=92 __open_dso) depend on for error propagation. Guard the close() call with fd >=3D 0 so only valid file descriptors are closed. Fixes: 42b3fa670825 ("perf tools: Introduce dso__decompress_kmodule_{fd,pat= h}") Reported-by: sashiko-bot Reviewed-by: Ian Rogers Cc: Namhyung Kim Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/dso.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c index b86969dc6e81e96e..41bbc8f994e41a3d 100644 --- a/tools/perf/util/dso.c +++ b/tools/perf/util/dso.c @@ -395,7 +395,9 @@ int dso__decompress_kmodule_path(struct dso *dso, const= char *name, { int fd =3D decompress_kmodule(dso, name, pathname, len); =20 - close(fd); + /* decompress_kmodule() returns -1 on failure, don't close(-1) */ + if (fd >=3D 0) + close(fd); return fd >=3D 0 ? 0 : -1; } =20 --=20 2.55.0 From nobody Tue Sep 29 02:00:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4DA623B6BE5; Thu, 13 Aug 2026 15:12:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633926; cv=none; b=isst5VacGzf2E92DOlWtKOQ0OQSljmjyj0nnbbXKaHTueP/lT/EvTAPa5wqEoqiQ/kkWqtl6F7N4uco2kgI1CQFkr8dB6r5rJ7uZCahpWqFzxGyMt3iIy6uNm9fUyOK+TO3ixLMt66Xet7tKfCnqTEoJI2LnG/p4LGb2r9lApvc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633926; c=relaxed/simple; bh=LCOo1iRSXOwVGYcLMl/phBY+fYn56Gcsb0KxeLjxy9o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lvNLcC0oB17YCppkXM6uYrlra2cbw/fOUB8DSMk/SrozrZg9c7Z7Cpyq25cYPe6alDynYSQy0N0KEWlkja2cVzbaEAcT/ye916CIz67133c0Ju/DuZ4kPR8cIXw25/JVLOO1w/gjsvkc0HEKelq+AmE6HrXzaiTZkuZEksTnda0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=aVgg4n+i; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="aVgg4n+i" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CEC7E1F000E9; Thu, 13 Aug 2026 15:12:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786633924; bh=5/3QjbKl+HrIXMVxHIqO5+5iknGvkzhHDhC4auX3+Us=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=aVgg4n+iOuY9SKvCdBXR/+nphrlk6jm4aSfNeK7xaQJDCbu0GBV/aqbVo3Pkh6Nky DRUP2v8C9Yq3Btjer4ZO0hb4TxlGcmSCegzX8lorLDFIT4r7W8Z3U+eUvzr+bliOu0 Qmd83GLaJIBmRVJVEjuz56YOhwiLSJ7EavDMKSzrbzIhTWFIjZBKm39HKcDEd6YB3R 8YoTdsQAmQoubgGyLfY4EzzDmygf7eyM8iv2l7Ykg199UKBOqPSAne8yu3+W0afCgv L8ELceKCFmDgd+BdxEsP6qh9p9LLygnwvEW1bD/0JwChZTSRv/4RAMf0Jq+MwrtET3 sMgqJAkiW+R/g== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot Subject: [PATCH 3/5] perf dso: Use stored fd error instead of stale errno in file_read() and file_size() Date: Thu, 13 Aug 2026 12:11:44 -0300 Message-ID: <20260813151148.23169-4-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260813151148.23169-1-acme@kernel.org> References: <20260813151148.23169-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo file_read() and file_size() use ret =3D -errno when dso__data(dso)->fd is negative after try_to_open_dso() fails. By this point errno has been through mutex_lock(), nsinfo__mountns_enter(), and multiple open() attempts inside try_to_open_dso() =E2=80=94 it no longer reflects the actual open failure. If errno happens to be 0, ret =3D 0 looks like EOF rather than an error, and file_size() callers like dso__data_size() would then report a zero-sized file instead of failing. dso__data(dso)->fd is always negative on failure =E2=80=94 -errno from __open_dso() when no filename could be built (e.g. -EINVAL, -ENOENT), or -1 when do_open() itself failed =E2=80=94 and never 0, so use it directly instead of reading the stale global errno. No assert() or comment is needed after the assignment: the enclosing if (dso__data(dso)->fd < 0) already guarantees ret < 0 [Namhyung Kim review]. Fixes: 33bdedcea2d7 ("perf tools: Protect dso cache fd with a mutex") Reported-by: sashiko-bot Reviewed-by: Ian Rogers Cc: Namhyung Kim Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/dso.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c index 41bbc8f994e41a3d..60aa77f7978514ec 100644 --- a/tools/perf/util/dso.c +++ b/tools/perf/util/dso.c @@ -1038,7 +1038,7 @@ static ssize_t file_read(struct dso *dso, struct mach= ine *machine, =20 if (dso__data(dso)->fd < 0) { dso__data(dso)->status =3D DSO_DATA_STATUS_ERROR; - ret =3D -errno; + ret =3D dso__data(dso)->fd; goto out; } =20 @@ -1160,8 +1160,8 @@ static int file_size(struct dso *dso, struct machine = *machine) try_to_open_dso(dso, machine); =20 if (dso__data(dso)->fd < 0) { - ret =3D -errno; dso__data(dso)->status =3D DSO_DATA_STATUS_ERROR; + ret =3D dso__data(dso)->fd; goto out; } =20 --=20 2.55.0 From nobody Tue Sep 29 02:00:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D45D9485CDC; Thu, 13 Aug 2026 15:12:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633930; cv=none; b=Z23uedFx04RAsCbjjgU9vI/g8A/h0VyYQG4IPc139TX1EXpVy9RLvWNojRb1TQ2AkMlOP6Yrnbv17AsvOpBowl7FaO0kv1HSc14mTQWuqhqHqUIMe1HFTmJYObAn8+7VyPJVNXbBgfzw1FzMVNe6lrBz9FIrUd31kVHiDniitrA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633930; c=relaxed/simple; bh=w/ov9dTFWUJ5efYR6riEWce9i1ZpojtqDWXcbEGZqcg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=eC0CeV8hBlWq8cAkPx6ueZO1hlcB1KYlaHpgGgLqKsYCC8a63sU11YbtN9lMiaPWgJutRtazZV0cb0YGcbpGVncTWlHlQPiEDSsUEI6rQ8bS3K88cMBcRPxz/7b/3fGnjWjt1Y/6mqFmtgQGB6wpEKghnwlre8vyYim3YHvQSXM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=NX7bAYfB; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="NX7bAYfB" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7B99E1F00A3A; Thu, 13 Aug 2026 15:12:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786633928; bh=5RWhhoRAyfdFS4j/kY6A9DoZiJijxrHc7BxW9IrX+yA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=NX7bAYfBgiFp6ScuK4KuFRVEblVxaDgcq+S/cIgG6yTakkl1AwBjNiTq8NwSm9gwj lyXhbKZvAv+Bt1G3Ecgp+xLWstHbllLzJDONsGRhJZgv8Eo9PJc1MVk8MlG2CkCa27 avp4Y0PbR2RheLmIaQ5eNJF5Rthn0UWqp+24v8u2+MSlFDJPJfQsHWGWyjP/Nje34N sYa7Zmtl9W+1RN0Dtgg/T4pbr3FijTBC24plNfxURo6T8q/s1OZTNFNDrXmmmQ9/UE 6bhmFmm9lgKrsE/peFdCNrW4x72SojX1ShADLEyfV/w8ozwk/RNib5GAVG824iGaXs 0uxGT3l/l8Llw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot Subject: [PATCH 4/5] perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() Date: Thu, 13 Aug 2026 12:11:45 -0300 Message-ID: <20260813151148.23169-5-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260813151148.23169-1-acme@kernel.org> References: <20260813151148.23169-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo dso_cache__memcpy() computes cache_offset =3D offset - cache->offset, then cache_size =3D min(cache->size - cache_offset, size). The RB tree lookup in __dso_cache__find() matches using the full DSO__DATA_CACHE_SIZE window, but cache->size reflects the actual pread return value from dso_cache__populate(). A short pread (e.g. near end-of-file) makes cache->size smaller than DSO__DATA_CACHE_SIZE. If a subsequent access targets an offset past cache->offset + cache->size but within the DSO__DATA_CACHE_SIZE window, the cache entry is found but cache_offset exceeds cache->size. Since both are u64, the subtraction cache->size - cache_offset wraps to a large value, min() selects the caller's size, and memcpy reads out of bounds. Return 0 for an offset past the valid cached data. For a regular file a short pread only happens at end-of-file, so 0 is what a direct pread() at that offset would return: cached_io() stops its read loop as on EOF. Re-reading from the backing file would not help =E2=80=94 a second pread at the same offset returns the same short count. Fixes: 366df72657e0 ("perf dso: Refactor dso_cache__read()") Reported-by: sashiko-bot Reviewed-by: Ian Rogers Cc: Adrian Hunter Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/dso.c | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c index 60aa77f7978514ec..4dd64069c4348c06 100644 --- a/tools/perf/util/dso.c +++ b/tools/perf/util/dso.c @@ -1014,7 +1014,20 @@ static ssize_t dso_cache__memcpy(struct dso_cache *c= ache, u64 offset, u8 *data, u64 size, bool out) { u64 cache_offset =3D offset - cache->offset; - u64 cache_size =3D min(cache->size - cache_offset, size); + u64 cache_size; + + /* + * The RB tree matches using DSO__DATA_CACHE_SIZE, but a short + * pread may leave cache->size smaller. For a regular file a + * short pread only happens at end-of-file, so an offset past + * the valid data is EOF: return 0, matching what a direct + * pread() at that offset would return, and cached_io() then + * stops its read loop. + */ + if (cache_offset >=3D cache->size) + return 0; + + cache_size =3D min(cache->size - cache_offset, size); =20 if (out) memcpy(data, cache->data + cache_offset, cache_size); --=20 2.55.0 From nobody Tue Sep 29 02:00:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4F3A4488DB2; Thu, 13 Aug 2026 15:12:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633933; cv=none; b=B43rw9zmxeeFTvtPqJ56tabWKAP0HCBtYipbXurEuh5dtGT0rHGv4ov3Oy7UsBpzj5gtbs1Lq4NDyGPB7ljiNrLi+8qpLQA8ND+q7tv9LKfQLBqE4PuKauYMbCIeGoo3WawxUvCvCwDcQddIJkkTrFRH0K63BqnRk+nR41iQKZQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786633933; c=relaxed/simple; bh=52IIqMbY2p0UfwGl9dUASwGOo93+toNU8D5TRgMYigM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=l6FmsLBQBdsvmrVUIV5TglU6IGP6HefzhE9nnZ4jJV+XjsveRRJVf50pHRZI9SDojdOMoZI3BLm2rK9ZSrJ5wUX6CB148JCjUETL5Xa/xg6a9rbB722Hp2UQkt1V3nqV24fHp/3mxOMF1qx+QIgzirEqeTXbvPJTQL4ZXl3C11I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ClkquzYR; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ClkquzYR" Received: by smtp.kernel.org (Postfix) with ESMTPSA id F105E1F00A3D; Thu, 13 Aug 2026 15:12:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786633932; bh=Xm4ge2uI2RMkDV/egTaPU3dqzmNnQZnZyDpsB5I3BDA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ClkquzYRcFLn+HNdkLrI1zM7LEI2eriO6LLGYbfnxDOtStOC8Dd5S0YGYgSyRTXVZ SzJF4+0DSL2O3bep1B1Ue0c980uzsbaAB05Xl0pIY3J9YTfZb9K46qXdhYZ74ocLdD CTBLIkKK9SOdYqhHu36GZlb2fGHaz0BpDPPaN5kTpaGIpJpStF/q0hkvmAOtqT8zno kvqU/MnddQjFeMyXhnbbyFEKyty5GI4/8RWjsDA48bJ6pp/TEHKNdtjFP/aCHOBJ/a AMCohvVcp6ilccL+i1vWth+xUFwSceuHwg+5GoaAhdMGZmgwBk6HMy9A5/0S7Lcszm 6IScazVpafZrQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Song Liu Subject: [PATCH 5/5] perf dso: Replace assert with runtime check in dso__read_symbol() Date: Thu, 13 Aug 2026 12:11:46 -0300 Message-ID: <20260813151148.23169-6-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260813151148.23169-1-acme@kernel.org> References: <20260813151148.23169-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo dso__read_symbol() asserts that len <=3D jited_prog_len, where len comes from sym->end - sym->start (parsed from PERF_RECORD_KSYMBOL in perf.data). Both values originate from untrusted file input. With NDEBUG (production builds), the assert is compiled out, allowing an out-of-bounds heap read when the BPF program buffer is accessed. Without NDEBUG, a crafted perf.data crashes perf with an assertion failure. Replace the assert with a runtime bounds check that returns NULL with an appropriate error code, matching the existing error handling pattern in this function. Fixes: aa04707f507e ("perf dso: Support BPF programs in dso__read_symbol()") Reported-by: sashiko-bot Reviewed-by: Ian Rogers Cc: Ian Rogers Cc: Song Liu Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/dso.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/dso.c b/tools/perf/util/dso.c index 4dd64069c4348c06..42bfe30a3b518e80 100644 --- a/tools/perf/util/dso.c +++ b/tools/perf/util/dso.c @@ -2038,7 +2038,12 @@ const u8 *dso__read_symbol(struct dso *dso, const ch= ar *symfs_filename, errno =3D SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF; return NULL; } - assert(len <=3D info_linear->info.jited_prog_len); + if (len > info_linear->info.jited_prog_len) { + pr_debug("BPF symbol length %zu exceeds jited_prog_len %u\n", + len, info_linear->info.jited_prog_len); + errno =3D SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF; + return NULL; + } *out_buf_len =3D len; return (const u8 *)(uintptr_t)(info_linear->info.jited_prog_insns); #else --=20 2.55.0